A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticated users.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24912
Reference (s):
- FULLDISC:20210312 [AIT-SA-20210215-03] CVE-2020-24912: QCube Cross-Site-Scripting
- URL: http://seclists.org/fulldisclosure/2021/Mar/30
- http://packetstormsecurity.com/files/161763/QCubed-3.1.1-Cross-Site-Scripting.html
- http://qcubed.com
- https://tech.feedyourhead.at/content/QCubed-Cross-Site-Scripting-CVE-2020-24912